
AWSCertified Security - Specialty
Domain 3Objective 3
Task 3.3: Design and Troubleshoot Network Security Controls SCS-C03 Practice Questions (Page 3)
Part of the Content Domain 3: Infrastructure Security domain, which accounts for 18% of the SCS-C03 exam. AWS does not publish an official question count, but from its 170-minute exam (~70–115 total, ~13–21 in this domain), expect 4–7 from this objective — we provide 23 practice questions to prepare you well beyond it. (estimate)
23questions here
5free pages
8concepts
18%of the exam
Questions 11–15
- 11
What does AWS Network Access Analyzer use to determine network reachability?
Select an answer first - 12
A company uses AWS Network Access Analyzer to validate its network segmentation. The engineer runs an analysis and finds an unintended access path from a public subnet to a database subnet. The database subnet contains sensitive data and should not be accessible from the public subnet. What should the engineer do first to remediate the issue?
Select an answer first - 13
A security engineer notices that an instance can receive inbound traffic on port 443 even though the inbound security group rule for port 443 was just removed. The instance's network ACL allows all traffic. What is the most likely reason for this behavior?
Select an answer first - 14
A security engineer needs to identify unintended network access paths in a VPC. Which AWS service can be used to analyze network reachability?
Select an answer first - 15
A company wants to centrally inspect and filter traffic between subnets in a VPC. Which AWS service is designed for this purpose?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by AWS. “SCS-C03” is a trademark of its owner, used for identification only.